hi @splunkcol,
The below query give top users who successfully logged into Splunk in the last 1 year.
index=_audit sourcetype=audittrail action="login attempt" info=succeeded earliest=-1y | top user
Top 10 by what measure? What problem are you trying to solve?
hi @splunkcol,
The below query give top users who successfully logged into Splunk in the last 1 year.
index=_audit sourcetype=audittrail action="login attempt" info=succeeded earliest=-1y | top user